According to PANews, LayerZero Labs’ default library contract upgrade mechanism poses risks to over $3 billion in LZ OFT on May 8, with $178 million currently exposed to projects still using the default configuration. Security researcher Banteg flagged that the contract lacks time restrictions, allowing LayerZero Labs to immediately upgrade it and forge messages, similar to the rsETH hack. On-chain data revealed that LayerZero Labs’ multisig signers participated in meme token trades, DEX swaps, and cross-chain bridge transactions, indicating production environment private keys were connected to external websites, increasing phishing risks. CEO Bryan Pellegrino confirmed the transactions were conducted by multisig team members, describing them as testing PEPE on the LZ OFT token standard rather than meme coin trading, and stated the involved members have been removed.
Related News
ZachXBT accuses LAB of pumping and dumping, offering a $10,000 bounty to track down the behind-the-scenes masterminds
BlockSec releases a stablecoin freeze risk white paper: 30 days of freezing over 960 addresses
ZachXBT Posts $10K Bounty on LAB Founder Over Market Manipulation Allegations